SiteBehaviour

Product details

Q: Not GDPR compliant?

Hi,
Can you confirm where you stand vs GDPR compliance?

Even if "complete tracking" is disabled and no IP is shown in the dashboard, SiteBehaviour still generates a unique session ID + captures browsing behavior (mouse movements, clicks, page flows). Under GDPR, that qualifies as pseudonymous personal data. Regulators have repeatedly said session recording requires consent (because it’s more intrusive than aggregated analytics) and legitimate interest is difficult to defend.

Is there a possibility to disable replays and heatmaps?

Thanks!

Chris_PLUSAug 28, 2025
Founder Team
Jashan_SiteBehaviour

Jashan_SiteBehaviour

Aug 28, 2025

A: Hi Chris, thanks for raising this important point 🙏 SiteBehaviour takes GDPR compliance very seriously. All data is stored in the EU, and when Complete Tracking is disabled, the unique session ID is only temporary.

If you’d like, we can also disable session replays and heatmaps for your account. Just reach out via our support chat and we’ll set that up for you.

Thanks,
Jashan

Share
Helpful?
Log in to join the conversation